What is CVE-2026-16979?
In SmartCrawl WordPress plugin before 3.16.3, missing capability checks on two AJAX actions allow users with Subscriber role to read private/draft post titles by ID and enumerate stored post-meta key names. Updating to the latest version is recommended.
Azərbaycanca: SmartCrawl WordPress plaginində (3.16.3 öncəsi) iki AJAX əməliyyatı üçün capability check olmadığından Subscriber rolu olan istifadəçilər private/draft post başlıqlarını oxuya və post-meta açar adlarını siyahılaya bilər. Plagini ən son versiyaya yeniləmək vacibdir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What vulnerability was discovered in SmartCrawl plugin and how can it be exploited?
In SmartCrawl WordPress plugin versions before 3.16.3, missing capability checks on two AJAX actions allow users with Subscriber role to read private and draft post titles by ID, as well as enumerate stored post-meta key names.
How can I protect my site from this security flaw?
To protect against CVE-2026-16979, it is essential to update the SmartCrawl plugin to the latest version (3.16.3 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.